A governance framework for delegated judgement
Never delegate judgement without deciding its limits first.
1. Purpose
Technology continues to absorb the performance of work. The enduring organizational challenge is no longer whether work can be automated, but which judgement should be delegated, within what boundaries, and under whose accountability.
Bounded Delegation is a governance framework for managing delegated judgement.
It is:
- a governance framework;
- technology independent;
- applicable to both human and automated decision-making;
- complementary to regulatory and compliance frameworks.
It is not:
- a theory of organizations;
- a maturity model;
- a certification framework;
- a replacement for regulatory obligations.
The framework rests on a single principle: Capability does not imply delegation.
A system becoming capable of exercising judgement does not mean an organization should delegate that judgement.
Everything else in the framework is a consequence of this principle:
- Delegation requires explicit boundaries.
- Delegation is continuous, not permanent.
- Accountability cannot be delegated to technology.
Human in the Loop represents retained authority, not manual verification.
2. Core concepts
Judgement
Judgement is the selection between multiple acceptable actions where evidence and deterministic rules no longer uniquely determine the outcome.
A practical test: Judgement exists whenever two competent people could reasonably reach different conclusions from the same evidence and rules.
Delegated judgement
Judgement consciously authorised for another actor to exercise within defined boundaries.
The actor may be a person, a team, a software system, an AI system or an external organization.
Delegation boundary
The explicit limit of delegated judgement.
It defines:
- what the actor may recommend;
- what it may decide;
- what it may execute;
- what must escalate;
- what remains outside its authority.
It also defines when the delegation must be re-authorized. A boundary that exists only on paper is not explicit. It must be expressed where the actor operates.
Sub-delegation
Delegation can be nested. An authorized actor may delegate further, to people, to systems or to agents.
Two rules apply:
- A sub-delegation cannot exceed the original boundary.
- Accountability does not transfer with it. The actor that received the delegation remains answerable for everything it delegates onward.
The second rule is older than the technology that now makes it urgent: signing authority has never been transferable onward without its own authorization.
Bounded Delegation: the goal state
Judgement is in Bounded Delegation when:
- its purpose is defined;
- its boundary is explicit;
- its accountability is assigned;
- its review is scheduled.
The framework is named after the state it exists to create.
The goal state is not new. Signature authority is a well-known implementation: judgement delegated to a named person, bounded by amount and scope, exercised alone or jointly, accountable by law, and publicly registered in the commercial register. Organizations have governed delegated authority this way for centuries.
The framework extends the same discipline to actors the commercial register does not see.
Shadow judgement
Judgement exercised without a conscious organizational decision to delegate it.
The actor may be a system or a person. In either case, the organization has delegated authority by accident.
Accountability
Responsibility for the consequences of delegated judgement.
Technology may support accountability but cannot own accountability.
3. Why judgement is different
The framework distinguishes four types of enterprise work. The first two automate naturally. The third requires a decision. The fourth stays.
Evidence
Question
What are the facts?
Purpose
Establish reliable evidence.
Automation objective
Maximum automation.
Examples
- OCR
- document extraction
- sensor acquisition
Evidence itself contains an important seam: extraction establishes what exists, interpretation establishes what it means.
Interpretation is judgement wearing Evidence's clothes.
Rules
Question
Given the evidence, what follows?
Purpose
Apply deterministic logic.
Automation objective
Maximum automation.
Examples
- tax calculation
- accounting postings
- workflow routing
Rules contain the same seam. Routine application is deterministic. Boundary cases require judgement.
Judgement
Question
What should be done?
Purpose
Reach an appropriate decision under uncertainty.
Automation objective
Appropriate delegation, not maximum automation.
Questions include:
- Should this judgement be delegated?
- To whom?
- Within what boundary?
- Under whose accountability?
Accountability
Question
Who owns the consequences?
Purpose
Maintain responsibility for organizational outcomes.
Automation objective
None. Technology supports accountability through audit trails, decision logs, versioned policies or performance history. Technology cannot become accountable.
4. One goal state, two failure modes
Bounded Delegation is the goal state.
- Shadow judgement means the organization never entered it.
- Delegation Drift means the organization left it without noticing.
The two failure modes look similar in their consequences but they differ in their cause, and they require different remedies.
Shadow judgement
Delegation that was never decided.
Employees and teams can now build useful applications without involving central IT. Sometimes those applications do more than process information and begin to shape decisions nobody agreed to hand over.
The same failure occurs without any technology at all.
Examples include:
- applications built outside central IT that recommend actions, rank candidates, prioritize work or flag anomalies;
- AI assistants quietly becoming de facto decision makers;
- purchased tools with embedded AI whose recommendations enter decisions unnoticed;
- a consultant or junior employee gradually becoming the de facto decision maker.
No boundary was set, because no delegation decision was ever made.
Shadow judgement is found through discovery: applying the Delegation Audit to systems and roles nobody registered.
Deegation Drift
Delegation that was decided but has since diverged.
Delegation Drift is a divergence between authorized authority and effective authority.
Delegation boundaries are not static: models change, people change, processes change, regulations change, organizations change.
Without explicit governance, the effective authority exercised by a system gradually diverges from the authority originally authorized.
Examples include:
- users relying on AI recommendations beyond their intended scope;
- model or vendor updates changing behaviour;
- prompt engineering expanding effective authority;
- decision support gradually being treated as decision making.
Delegation Drift is found through review: the recurring review step of the governance cycle. Both failure modes are governance failures before they are technical failures.
The framework in one view
5. Continuous delegation
Delegation is not an approval. It is a governance cycle:
- Define purpose.
- Identify the judgement involved.
- Decide what may be delegated.
- Define explicit boundaries.
- Assign accountability.
- Monitor performance.
- Review delegation.
- Adjust boundaries.
- Repeat.
The cycle works best attached to rhythms the organization already has: release cycles, vendor reviews, periodic business reviews. A review step that requires its own bureaucracy will be bypassed.
Human in the Loop belongs here. It represents the visible edge of delegated authority and is not merely an approval button.
Human involvement constitutes retained authority only when the human has the competence, time, information and authority to challenge, override or halt the outcome.
A human who approves every recommendation is not exercising retained authority.
Override rates are the observable signal. When they collapse, one of two things is true: the task has revealed itself as rules rather than judgement, or retained authority has decayed into passive approval.
The first calls for redrawing the boundary deliberately. The second is Delegation Drift. Either way, the boundary is due for review.
6. Organizational risk
The framework distinguishes two independent forms of risk.
Regulatory risk
Defined externally.
Examples:
- EU AI Act
- Industry regulation
Organizations cannot change regulatory classification.
Organizational risk
Defined internally.
Organizational risk is the mismatch between the judgement actually exercised and the judgement explicitly authorized.
The mismatch arises through:
- judgement delegated without a decision (shadow judgement);
- unclear delegation;
- poorly governed delegation;
- delegation drift.
Unlike regulatory risk, organizational risk can be reduced through governance.
The two risks vary independently
A recruitment AI is classified as high risk under the EU AI Act, regardless of how well it is governed. Its organizational risk can nonetheless be low: purpose defined, role documented, boundaries explicit, accountability assigned, performance monitored.
A recommendation engine outside any regulated domain carries low regulatory risk. Its organizational risk is high if it quietly drives strategic decisions nobody agreed to delegate.
Compliance addresses the first risk but only governance of delegation addresses the second.
7. The Delegation Audit
The Delegation Audit operationalizes the framework. E
very system capable of influencing organizational decisions should be answerable through seven questions.
1. What judgement is the system exercising, including judgement hidden inside evidence or rules? 2. Why is that judgement delegated? 3. Is the boundary explicit? 4. Is it decision support or decision making? 5. Who remains accountable? 6. How is delegation monitored and periodically reviewed? 7. What changes require re-authorization of the delegation?
A system that cannot answer these questions is likely exercising judgement that has been delegated accidentally.
The Audit applies equally to enterprise AI platforms, internally developed applications, AI agents, purchased tools, small end-user applications and human roles. Applied to registered systems, it detects Delegation Drift. Applied to unregistered systems, it discovers shadow judgement.
8. Relationship to compliance
External governance frameworks answer questions such as:
- What does regulation require?
- Which controls must exist?
Bounded Delegation answers a different question: What judgement has this organization consciously decided to delegate?
Some frameworks ask parts of this question. None can answer it. Only the organization itself can.
Compliance and governance answer different questions. Both are necessary, and neither replaces the other.
Bounded Delegation, version 1.0 , August 2026.
Changes to the framework are versioned. The framework practices the review cycle it describes.
